Daily, weekly and annual operations
The home page is a work queue, not a vanity score. It answers: what needs a decision, what deadline is approaching, what integration is failing, and which evidence is stale?
flowchart LR
I[Signals: requests, incidents, connector results, source changes] --> Q[Prioritised work queue]
Q --> T{Triage}
T -->|Decision needed| A[Assigned owner + checker]
T -->|Automatable| W[Policy-bound workflow]
T -->|Uncertain| E[Escalate to legal / security / DPO]
A --> V[Verify evidence and outcome]
W --> V
E --> A
V --> C[Close or schedule next review]
C --> M[Daily handover + weekly reconciliation]
M --> Q
Privacy operations reviews new rights/grievance cases, identity/clarification needs, downstream task failures and Principal messages. Incident command sees active signals and every triggered or uncertain clock. System owners see assigned fulfilment/deletion tasks. Processor managers see incident/subprocessor/contract changes.
Queue columns: severity, entity, case/control, current state, next action, owner, source clock, business target, evidence state and last sync. Default sorting is statutory/contract deadline then risk—not customer value.
Weekly
Section titled “Weekly”- reconcile failed/late connector tasks and dead letters;
- review new/changed purposes, notices, vendors and subprocessors;
- sample identity overrides and mass actions;
- review open holds and retention exceptions;
- check contact route and notification delivery health;
- assess source/change alerts;
- review support access and break-glass use.
Monthly and quarterly
Section titled “Monthly and quarterly”Monthly: evidence freshness, rights/withdrawal latency, deletion completion, processor attestations, access reviews and capacity. Quarterly: sector/legal applicability, incident tabletop, vendor concentration, restore/re-deletion, privileged role certification and executive risk review.
Metrics show numerator/denominator and exclusions. “92% complete” links to the eight missing objects; it is never a compliance grade.
Annual / designation-driven
Section titled “Annual / designation-driven”- full processing/purpose/retention review;
- contract/subprocessor and transfer review;
- security risk/control and recovery tests;
- accessibility and dark-pattern audit;
- SDF DPIA/audit cycle from designation date if applicable;
- independent audit and remediation;
- licence/sector pack review;
- customer exit rehearsal;
- open-source dependency/licence and threat-model review.
Dashboard definitions
Section titled “Dashboard definitions”| Metric | Definition | Alert |
|---|---|---|
| request clock risk | open cases within configured escalation threshold | owner + DPO |
| withdrawal propagation | completed destinations / due destinations | partial past SLO |
| evidence freshness | controls with unexpired passing evidence / applicable controls | critical stale |
| processor readiness | critical processors with contract, incident and exit test | missing element |
| retention execution | due records/tasks completed and verified | backlog/failed destination |
| legal config drift | active customers behind approved version | severity by changed control |
Never rank teams by low grievance/incident count; that incentivises suppression. Monitor acknowledgement, decision quality, closure evidence and recurrence instead.
Degraded operation
Section titled “Degraded operation”When a connector is down, queue bounded tasks, show source freshness, invoke manual fallback and preserve idempotency. When the control plane is unavailable, customer-side incident/runbook exports provide contacts and forms. On recovery, signed offline actions reconcile without overwriting newer decisions.
Shift handover
Section titled “Shift handover”Active incidents/cases carry factual summary, clocks, last/next action, open assumptions, communication status, owner and correlation ID. Handover does not transfer accountability silently; the incoming owner acknowledges.